2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-1754MEDIUM4.7The NPS computy WordPress plugin through 2.7.5 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-1746MEDIUM5.4The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allo...
CVE-2024-1712MEDIUM4.7The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-1660MEDIUM4.8The Top Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-1310MEDIUM4.9The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking produ...
CVE-2024-1307MEDIUM6.5The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow us...
CVE-2024-1306MEDIUM5.4The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to...
CVE-2024-1204MEDIUM4.3The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitr...
CVE-2024-0902MEDIUM4.8The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could...
CVE-2024-3776MEDIUM6.1The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated re...
CVE-2024-3774MEDIUM5.3aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restriction...
CVE-2024-3763MEDIUM5.4A vulnerability was found in Emlog Pro 2.2.10. It has been rated as problematic. This issue affects some unknown process...
CVE-2024-3762MEDIUM5.4A vulnerability was found in Emlog Pro 2.2.10. It has been declared as problematic. This vulnerability affects unknown c...
CVE-2024-3735MEDIUM6.3A vulnerability was found in Smart Office up to 20240405. It has been classified as problematic. Affected is an unknown ...
CVE-2024-3721MEDIUM6.3A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects som...
CVE-2024-3720MEDIUM6.3A vulnerability has been found in Tianwell Fire Intelligent Command Platform 1.1.1.1 and classified as critical. This vu...
CVE-2024-26817MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid inte...
CVE-2024-3662MEDIUM4.3The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capabil...
CVE-2024-2583MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortc...
CVE-2024-3027MEDIUM6.4The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...
CVE-2024-1957MEDIUM5.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-32028MEDIUM4.1OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `OpenTelemetry.Instrumentation.Http` and `...
CVE-2024-31462MEDIUM6.3stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui...
CVE-2024-32000MEDIUM4.3matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. matrix-appservice-irc before version 2....
CVE-2024-22359MEDIUM6.1IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now